Important note: Action hooks can no longer send requests to internal addresses (loopback, private, link-local) by default. Allow the internal hosts your hooks need with
actions.network.allowed_hosts. Hook requests no longer use theHTTP_PROXY/HTTPS_PROXYenvironment variables.
Security Fixes
- Fixed a vulnerability that allowed users who can write action files to make the lakeFS server send requests to internal addresses (GHSA-223c-qwgx-wwcg)
- S3 gateway now rejects SigV4 requests with unsigned
x-amz-*headers (GHSA-96f7-c79c-crg8)